CVE-2022-24913
MEDIUMJava-merge-sort < 1.1.0 - Exposure to Wrong Actor
Title source: ruleDescription
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
Scores
CVSS v3
5.5
EPSS
0.0007
EPSS Percentile
20.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-377
CWE-668
Status
published
Affected Products (2)
java-merge-sort_project/java-merge-sort
< 1.1.0
com.fasterxml.util/java-merge-sort
< 1.1.0Maven
Timeline
Published
Jan 12, 2023
Tracked Since
Feb 18, 2026